Description
ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to obtain an administrator’s API key and use it to perform administrator-level actions.
Published: 2026-09-23
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

A low‑privileged user can obtain an administrator API key and use it to perform actions that require administrative privileges. The flaw exploits improper privilege management, allowing the attacker to elevate their access level within ManageEngine Applications Manager.

Affected Systems

Zohocorp ManageEngine Applications Manager versions 182000 and earlier are vulnerable. Users of these versions should identify whether they run one of these releases.

Risk and Exploitability

The CVSS score of 8.8 signifies a high severity vulnerability. No EPSS score is available to gauge current exploit likelihood, and it is not listed in the CISA KEV catalog. The attack is likely carried out through the web application interfaces using a credentialed, low‑privileged account; the attacker can bypass privilege checks to obtain the API key and then perform privileged actions.

Generated by OpenCVE AI on September 23, 2026 at 15:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s security update for ManageEngine Applications Manager released for versions 182000 and earlier
  • Upgrade to a version newer than 182000 that includes the fix
  • Restrict low‑privileged user rights so they cannot access or retrieve API keys

Generated by OpenCVE AI on September 23, 2026 at 15:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 23 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to obtain an administrator’s API key and use it to perform administrator-level actions.
Title Broken Authentication vulnerability
First Time appeared Zohocorp
Zohocorp manageengine Applications Manager
Weaknesses CWE-639
CPEs cpe:2.3:a:zohocorp:manageengine_applications_manager:*:*:*:*:*:*:*:*
Vendors & Products Zohocorp
Zohocorp manageengine Applications Manager
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Zohocorp Manageengine Applications Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: Zohocorp

Published:

Updated: 2026-09-23T15:23:26.431Z

Reserved: 2026-09-08T09:48:25.718Z

Link: CVE-2026-86678

cve-icon Vulnrichment

Updated: 2026-09-23T15:23:20.640Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-23T14:17:08.963

Modified: 2026-09-23T18:17:31.543

Link: CVE-2026-86678

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T16:15:05Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key